PT-2005-4717 · Coppermine · Coppermine Photo Gallery
Publicado
2005-12-03
·
Atualizado
2019-07-16
·
CVE-2005-3979
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Coppermine Photo Gallery versions 1.4.2 and 1.4 beta
Description
The issue concerns the relocate server.php file, which remains present after installation and lacks authentication. This allows remote attackers to access sensitive information, including database configuration, by making a direct request to the file.
Recommendations
For Coppermine Photo Gallery version 1.4.2, remove or restrict access to the relocate server.php file to prevent unauthorized access.
For Coppermine Photo Gallery version 1.4 beta, remove or restrict access to the relocate server.php file to prevent unauthorized access.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Coppermine Photo Gallery